Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqcf-grp7-vr4j

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request.

admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request.

EPSS

Процентиль: 86%
0.0289
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 16 лет назад

admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request.

EPSS

Процентиль: 86%
0.0289
Низкий

Дефекты

CWE-287